기사 메일전송
North Korean hacking group distributes malware disguised as code snippets used by developers
  • Yonhap News
  • July 5, 2026 at 9:32 AM
기사수정
  • JFrog Report… Lazarus, One of the Three Major Hacking Groups Affiliated with North Korea's Reconnaissance General Bureau, Suspected


North Korean hackingNorth Korean hacking [Yonhap News] 

A malicious hacking group, believed to be supported by the North Korean government, has been found stealing information by mimicking popular code packages frequently used by software (SW) developers worldwide.


JFrog Security Research, a global software company based in Silicon Valley, announced on the 4th (local time) that it had discovered six malicious packages on 'npm,' the official software repository for JavaScript developers, that were sophisticated imitations of well-known code bundles.


When coding, developers generally do not write every single part of a program from scratch; instead, they frequently download commonly used functions from public repositories as needed.


It is much like a carpenter buying standardized nails from a hardware store when building furniture.


Exploiting this practice, hackers mimicked popular code packages—some downloaded over 1.2 million times a month—inserted malicious code, and uploaded them under names very similar to the originals.


For example, they used names like 'rollup-packages-polyfill-core' or 'rollup-runtime-polyfill-core,' which could easily be confused with the legitimate code package 'rollup-plugin-polyfill-node.'


They exploited the fact that developers often search for packages using only partial names, such as "rollup polyfill," rather than typing the full package name.


The manuals and website addresses included were also identical to the originals, making them indistinguishable unless examined very closely.


They also incorporated several elaborate evasion techniques to avoid detection by malware scanners.


For one, the code was designed to remain dormant if it detected it was running in a 'sandbox' environment used for threat detection.


Furthermore, they employed multi-stage methods: hiding malicious functions within normal-looking code or omitting the core malicious payload entirely from the package, instead having it secretly downloaded and executed from an external source during installation or runtime.


As a result, it is difficult to identify the malware by simply scanning the package itself.


This attack is a "software supply chain attack" tactic that targets the entire corporation by using the computers of developers building corporate systems as a stepping stone, rather than targeting ordinary internet users.


It is estimated that the hackers intended to monitor computer screens, seize control of computers, and steal cryptocurrency wallets and login credentials.


JFrog Security Research explained that the multi-stage structure, camouflage techniques, and methods of information theft and remote control used in this attack match the operational patterns of 'Lazarus,' a group identified by the U.S. government as being linked to North Korean hacking activities.


Lazarus is one of the three major hacking organizations known to be under North Korea's Reconnaissance General Bureau, alongside Kimsuky and Andariel, and was identified as the group responsible for hacking the South Korean cryptocurrency exchange Upbit last year.


Some of the fake packages uploaded to the repository have been suspended following emergency sanctions. However, the research institute urged developers and companies that may have already installed them to thoroughly check for potential damage. 


What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site